CWE-359

Exposure of Private Personal Information to an Unauthorized Actor

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.

196 vulnerabilities with CWE-359
CVE-2025-43259 MEDIUM
macOS <15.6-13.7.7 - Info Disclosure
CVSS 4.6
CVE-2025-43227 HIGH
Safari < 18.6 - Unauthorized Exposure of Private Personal Information via Malicious Web Content
CVSS 7.5
CVE-2025-43217 MEDIUM
iPadOS < 17.7.9 and < 18.6 - Unauthorized Exposure of Privacy Indicators
CVSS 4.0
CVE-2025-31276 MEDIUM
iPadOS < 17.7.9 and < 18.6 - Unauthorized Remote Content Loading via Load Remote Images Setting Bypass
CVSS 5.3
CVE-2025-53625 HIGH
DynamicPageList3 < 3.6.4 - Exposure of Hidden Usernames via DPL Parameters
CVE-2025-53374 MEDIUM
dokploy < 0.23.7 - Authenticated Exposure of Private Personal Information via user.one Endpoint
CVSS 4.3
CVE-2025-6017 MEDIUM
Red Hat Advanced Cluster Management <2.10.7-2.12.4 - Info Disclosure
CVSS 5.5
CVE-2025-49715 HIGH
Dynamics 365 FastTrack Implementation Assets - Info Disclosure
CVSS 7.5
CVE-2025-49134 MEDIUM
Weblate < 5.12 - Unauthorized Exposure of User IP Address in Audit Log Notifications
CVSS 5.3
CVE-2025-5334 HIGH
Devolutions Remote Desktop Manager < 2025.1.34.0 - Unauthorized Access to Private Information via User Vaults
CVSS 7.5
CVE-2025-0679 MEDIUM
GitLab CE/EE <17.10.7-18.0.1 - Info Disclosure
CVSS 4.3
CVE-2025-3035 MEDIUM
Firefox < 137.0 - Unauthorized Document Title Exposure via AI Chatbot
CVSS 5.3
CVE-2025-26816 MEDIUM
Intrexx Portal Server <12.0.2 - Info Disclosure
CVSS 6.5
CVE-2025-27080 MEDIUM
AOS-CX - Info Disclosure
CVSS 6.0
CVE-2025-25042 MEDIUM
HPE AOS-CX Sensitive Information Exposure via REST Interface
CVSS 4.3
CVE-2025-1939 LOW
Firefox < 136.0 - Permission Spoofing via Custom Tabs Transition Animation
CVSS 3.9
CVE-2025-20060 HIGH
Dario Health USB-C Blood Glucose Monitoring System Android < 5.8.7.0.36 - Personal Health Information Exposure
CVSS 7.5
CVE-2025-20615 MEDIUM
Qardio Arm iOS - Unauthenticated Exposure of Sensitive Data in Plist File
CVSS 6.2
CVE-2025-0683 MEDIUM
Contec Health CMS8000 Patient Monitor - Info Disclosure
CVSS 5.9
CVE-2025-24355 HIGH
Updatecli <0.93.0 - Info Disclosure
CVSS 7.1
CVE-2024-13953 MEDIUM
ASPECT-Enterprise <3.* - Info Disclosure
CVSS 4.9
CVE-2024-42325 LOW
Zabbix 5.0.0-5.0.45 - Unauthorized Exposure of User Information via API user.get
CVSS 3.5
CVE-2024-10267 HIGH
transformeroptimus/superagi - Info Disclosure
CVSS 7.5
CVE-2024-13228 MEDIUM
Qubely - Advanced Gutenberg Blocks <1.8.13 - Info Disclosure
CVSS 4.3
CVE-2024-11216 HIGH
PozitifIK Pik Online <3.1.5 - Privilege Escalation
CVSS 7.6
Details
Vulnerabilities 196